The social layer of TrustPlane
The social network
where every side
of you lives.
Your account is a key you hold, not a row in our database. Each group sees only the side you showed it. And when you post from somewhere real, the place itself signs that you were standing in it.
Works in your browser right now — nothing to install. Already have an account? Sign in.
The premise
People have sides.
The internet flattens them.
On every other network you log in as one self — the same face for your family, your boss, the friends you had in school, and the strangers reading your posts. That isn’t how people actually are.
Each side is its own key. Cryptographically separate. Only you can link them.
public
For the world. Indexed, addressable, yours.
private
For the people you trust. End-to-end. No middlemen.
work
A different face. Different rules. Same person.
close
The handful of people who actually know you.
What it does
Six things that work,
described exactly.
Each of these is a live endpoint, not a roadmap item. The full request and response for every one is in the docs.
Sides, not accounts
One person, a separate key for each group you join. The side your colleagues see and the side your close friends see are different identities. Nobody can link them — not even us.
Groups that hold their shape
A group has a written contract, ranks that grant real powers, and members who are only the side they showed at the door. Groups can hold groups. A group you are not in does not exist to you.
Experiences, not posts
A photo, the place it happened, and the people who were there — carrying the place’s own proof that you were standing in it.
Verified together
Tag someone in an experience. If they confirm from the same place within two hours, the tag stops being a claim and becomes verified together. The place vouched for both of you.
Your people
A graph of exactly what each person let you see: the name they use in each group you share, where you have both been, who brought whom in. Nothing is inferred.
A name anyone can check
Claim a handle and this registry signs it over your own attestation. Any resolver on the trust web can verify it against a key it pinned in advance.
What only TrustPlane gives it
Anyone can type
a location.
A badge on a TP Social post isn’t a location you entered. It is a signed statement from the place itself, checked against a key the registry pinned in advance. If the place didn’t sign it, there is no badge.
Verified together
Tag someone. If they confirm with their own credential for the same place within two hours, the tag stops being your claim and becomes a fact both of you can point at. A credential for somewhere else, or too far apart, is refused and nothing is recorded.
-
i
The place proves what it is
A venue runs a gate with its own key. Its identity is on the trust web, resolvable by anyone.
-
ii
Your device proves you are in it
A short exchange over the local radio — fresh each time, so a recording of yesterday proves nothing today.
-
iii
The place signs a credential
Not a check-in you typed. A signed statement from the venue that this side was here, at this moment.
-
iv
It rides with what you post
The registry verifies the signature and refuses any credential whose subject is not the person posting. The badge means the place vouched.
The registry refuses a credential whose subject is not the person posting.
Where it actually is
What works today.
And what doesn’t yet.
A network that asks you to trust it should be straight about its own state. This list is kept honest on purpose.
Running now
- Handles + the name authority Signed, resolvable, pinned
- Groups, invites, ranks, contracts Including groups inside groups
- Experiences, photos, tags With verified-together
- Presence badges Verified against a pinned key
- Your people, the graph Peer-scoped, never inferred
- The web app + the API Use it in a browser today
Not yet
- Desktop and mobile builds Written; being signed before release
- Presence assurance Level 0 today — the client reports its own signal
- Federation between registries The namespace is per-server for now
Bring TP Social home
Same network. Every device.
One identity, one inbox, one set of sides — mirrored across your devices, never across our servers. Add the next device with a QR.
Available now
Use it in your browser
Any modern browser. Nothing to install. Pair a device later.
Native builds · in signing
macOS
Universal · 12.0+
Windows
64-bit · 10+
Linux
AppImage / .deb
iOS
App Store · 16.0+
Android
Google Play · 9.0+
We don’t hand out a binary until it’s signed with the protocol’s own keys, so you can check on your end that it’s the build we shipped. Slower than “download here.” Worth it.
For the curious
What’s
under the hood.
An open standard, published in plain English. Anyone can build a client. Anyone can run a node. We wrote it down so we couldn’t quietly change it later.
Read the protocolA keypair you generate on your device. Never ours.
Per-message, sealed to the recipient. Even we can’t read it.
Survives bad networks. Roams between Wi-Fi and cellular.
BLAKE3 hashes. The bytes are the address.
Where to next
A network you can leave at any time, because it was never ours to begin with.